StackRadar

CVE-2025-26465

Medium

Advisory

Published 18 Feb 2025In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.8
base score, highest
EPSS
0.077
94th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
307
of 17,781 indexed, latest versions
Container images
306
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: openssh security update

Carried by container images the latest versions of 307 of 17,781 indexed charts deploy, on 306 images.

Affected packageAffected versionsFixed inImages
opensshdeb1:7.2p2-4ubuntu2.2, 1:7.2p2-4ubuntu2.4, 1:7.2p2-4ubuntu2.6, 1:7.2p2-4ubuntu2.7+34 more1:7.2p2-4ubuntu2.10+esm7, 1:7.6p1-4ubuntu0.7+esm4, 1:8.2p1-4ubuntu0.12, 1:8.2p1-4ubuntu0.fips.0.12+5 more265
opensshapk9.3_p1-r3, 9.3_p2-r0, 9.3_p2-r1, 9.3_p2-r2+5 more9.3_p2-r3, 9.6_p1-r2, 9.7_p1-r5, 9.9_p2-r028
opensshrpm8.0p1-4.el8_1, 8.0p1-6.el8_4.2, 8.0p1-9.el8, 8.0p1-15.el8_6.3+5 more0:8.0p1-26.el8_10, 0:8.7p1-38.el9_4.5, 0:8.7p1-45.el913
OSV records
ALPINE-CVE-2025-26465DEBIAN-CVE-2025-26465RHSA-2025:16823RHSA-2025:3837RHSA-2025:6993UBUNTU-CVE-2025-26465DLA-4057-1
Also known as
DSA-5868-1, USN-7270-1, USN-7270-2

Charts affected

307 by stars
ChartLatestAffected imagesRadar Score
tfy-distributortruefoundryVerified publisher0.0.11 of 4See more

tfy-distributor truefoundry 0.0.1

1 of the 4 container images this version deploys carry CVE-2025-26465.

Container imageDigestPackageFixed in
public.ecr.aws/truefoundrycloud/async-service-distributor:5d48113bc678d694a0c8f8dabb2207c5aa2cfc53f74851ce31f5
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u5

Open the chart page →

17,323
demo-backendv2flyVerified publisher0.0.31 of 1See more

demo-backend v2fly 0.0.3

1 of the 1 container images this version deploys carry CVE-2025-26465.

Container imageDigestPackageFixed in
quay.io/yushiwho/api:e1f9d77e0d9b93dbf2b
openssh@1:9.2p1-2
1:9.2p1-2+deb12u5

Open the chart page →

14,358
vinyl-lib-chartvinyl-libVerified publisher0.1.01 of 1See more

vinyl-lib-chart vinyl-lib 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-26465.

Container imageDigestPackageFixed in
kporwit/vinyl_lib_app:v0.1.1217de0302218
openssh@1:8.4p1-5
1:8.4p1-5+deb11u4

Open the chart page →

3,392
drillwearefrank1.3.61 of 3See more

drill wearefrank 1.3.6

1 of the 3 container images this version deploys carry CVE-2025-26465.

Container imageDigestPackageFixed in
apache/drill:1.21.11f96558fd292
openssh@1:8.4p1-5+deb11u1
1:8.4p1-5+deb11u4

Open the chart page →

9,397
marge-botwiremindVerified publisher1.4.41 of 1See more

marge-bot wiremind 1.4.4

1 of the 1 container images this version deploys carry CVE-2025-26465.

Container imageDigestPackageFixed in
hiboxsystems/marge-bot:0.14.0dcffb926e563
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u5

Open the chart page →

5,542
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-26465.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
openssh@1:8.9p1-3ubuntu0.10
1:8.9p1-3ubuntu0.11

Open the chart page →

14,100
enterprise-gatewayzeet3.2.21 of 2See more

enterprise-gateway zeet 3.2.2

1 of the 2 container images this version deploys carry CVE-2025-26465.

Container imageDigestPackageFixed in
elyra/kernel-image-puller:3.2.2c922f1f1646a
openssh@1:8.4p1-5+deb11u1
1:8.4p1-5+deb11u4

Open the chart page →

1,838

Container images carrying it

306 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
helga09/shoes_ukr:v1.1.17999bc8b77c0
openssh@1:8.4p1-5+deb11u1
1:8.4p1-5+deb11u4
1
helicone/clickhouse-migration-runner:v2025.03.05-14c69b971a7e4
openssh@1:8.2p1-4ubuntu0.11
1:8.2p1-4ubuntu0.12
1
helicone/supabase-migration-runner:v2025.03.05-14a913936c97b
openssh@1:9.2p1-2
1:9.2p1-2+deb12u5
1
hiboxsystems/marge-bot:0.11.07235809b43b3
openssh@1:8.4p1-5+deb11u1
1:8.4p1-5+deb11u4
1
hiboxsystems/marge-bot:0.12.1a96c10b61a59
openssh@1:8.4p1-5+deb11u1
1:8.4p1-5+deb11u4
1
hiboxsystems/marge-bot:0.14.0dcffb926e563
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u5
1
hmediade/printserver-init:latest7f005eb6c718
openssh@1:8.9p1-3ubuntu0.6
1:8.9p1-3ubuntu0.11
1
homeassistant/home-assistant:2023.10.3021e2afc6e57
openssh@9.3_p2-r0
9.3_p2-r3
1
homeassistant/home-assistant:2023.12.48d000332b09b
openssh@9.3_p2-r0
9.3_p2-r3
1
hyperledger/fabric-couchdb:0.4.10c65891b6c237
openssh@1:7.2p2-4ubuntu2.4
1:7.2p2-4ubuntu2.10+esm7
1
ibmcom/ibmcloud-object-storage-driver:1.8.16c796a4c693b4
openssh@8.0p1-4.el8_1
0:8.0p1-26.el8_10
1
ibmcom/icp-swift-sample:latestb5d8c6714dbc
openssh@1:7.2p2-4ubuntu2.4
1:7.2p2-4ubuntu2.10+esm7
1
ibmcom/microclimate-theia:lateste17bdccc5030
openssh@1:7.2p2-4ubuntu2.2
1:7.2p2-4ubuntu2.10+esm7
1
ildarmukhametzyanov/priceapp:0.115d23720a3ee
openssh@1:9.2p1-2
1:9.2p1-2+deb12u5
1
inseefrlab/shelly:cloudshell31f04ca7436b
openssh@1:8.9p1-3ubuntu0.4
1:8.9p1-3ubuntu0.11
1
intelowlproject/intelowl:v6.6.10b22e547ea6b
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u5
1
ironmansoftware/universal:3.3.1-ubuntu-20.041943c73cce31
openssh@1:8.2p1-4ubuntu0.5
1:8.2p1-4ubuntu0.12
1
j0113/haven-compliancy-dashboard:1.3696cb8ca9f4e
openssh@1:8.4p1-5
1:8.4p1-5+deb11u4
1
jedi132000/nextapp:latestdc2a81e92f23
openssh@1:8.2p1-4ubuntu0.5
1:8.2p1-4ubuntu0.12
1
jenkins/jenkins:2.462.2-jdk1795313257a8cd
openssh@1:9.2p1-2+deb12u3
1:9.2p1-2+deb12u5
1
jenkins/jenkins:2.440.3-jdk17de4fea113221
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u5
1
kfirfer/gcloud-mysql:1.0.3c257c1e0e8b9
openssh@9.3_p2-r1
9.3_p2-r3
1
knspar/phronetis-operator:0.1.60c4f0543ee58
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u5
1
kobotoolbox/kobocat:2.022.24ab15679454415
openssh@1:8.4p1-5+deb11u1
1:8.4p1-5+deb11u4
1
kong/httpbin:latesta6ac46531193
openssh@1:8.9p1-3ubuntu0.10
1:8.9p1-3ubuntu0.11
1
kporwit/vinyl_lib_app:v0.1.1217de0302218
openssh@1:8.4p1-5
1:8.4p1-5+deb11u4
1
kusionstack/kusion:v0.14.0126c8f0b0976
openssh@1:8.9p1-3ubuntu0.10
1:8.9p1-3ubuntu0.11
1
library/docker:24.0.2-dind1d148deae16a
openssh@9.3_p1-r3
9.3_p2-r3
1
library/docker:27-cli851f91d24121
openssh@9.9_p1-r2
9.9_p2-r0
1
library/docker:27-dindaa3df78ecf32
openssh@9.9_p1-r2
9.9_p2-r0
1
library/docker:23.0.6-dindafa5d5134900
openssh@9.3_p2-r0
9.3_p2-r3
1
library/docker:26.1-dinddd43b430341a
openssh@9.7_p1-r4
9.7_p1-r5
1
library/python:3.8d41127070014
openssh@1:9.2p1-2+deb12u3
1:9.2p1-2+deb12u5
1
librenms/librenms:24.11.00920bc9117a8
openssh@9.6_p1-r1
9.6_p1-r2
1
linuxserver/calibre:version-v5.21.0a847b5b2d860
openssh@1:7.6p1-4ubuntu0.3
1:7.6p1-4ubuntu0.7+esm4
1
linuxserver/code-server:4.10.1a5e43a05ae79
openssh@1:8.9p1-3ubuntu0.1
1:8.9p1-3ubuntu0.11
1
linuxserver/openssh-server:9.7_p1-r4-ls17153ea39d2485c
openssh@9.7_p1-r4
9.7_p1-r5
1
macropower/twitch_predictions_recorder:v0.21e9c4fb89787
openssh@1:8.4p1-5+deb11u1
1:8.4p1-5+deb11u4
1
maissacrement/pock8snodejs:0.0.16da0db1159da
openssh@1:8.4p1-5+deb11u1
1:8.4p1-5+deb11u4
1
maksymhencha/educative-helm-bookapp:0.0.27f096a681192
openssh@1:8.2p1-4ubuntu0.13
1:8.2p1-4ubuntu0.fips.0.12
1
mediagis/nominatim:4.2d0eae7b51374
openssh@1:8.9p1-3ubuntu0.6
1:8.9p1-3ubuntu0.11
1
michaelepitech/sample-app:latestaf51d61c19f5
openssh@1:8.4p1-5+deb11u3
1:8.4p1-5+deb11u4
1
mnaggar3396/python-app:latest371d8ed84b15
openssh@1:8.4p1-5+deb11u1
1:8.4p1-5+deb11u4
1
moreillon/face-recognition-fastapi:x86bacb2ddd8394
openssh@1:8.4p1-5
1:8.4p1-5+deb11u4
1
moreillon/user-manager-mongoose:v5.0.1d2ee0423b797
openssh@1:9.2p1-2+deb12u1
1:9.2p1-2+deb12u5
1
mshanley80/httpbin2022:latest5b189a70c0fb
openssh@1:8.2p1-4ubuntu0.5
1:8.2p1-4ubuntu0.12
1
muhammedgamal/fp23:latest74b4cd69b6fa
openssh@1:9.2p1-2+deb12u2
1:9.2p1-2+deb12u5
1
muluder/prograncontrollermcord:0.1.843b597a93da7
openssh@1:7.2p2-4ubuntu2.4
1:7.2p2-4ubuntu2.10+esm7
1
nathanielvarona/pritunl-slack-app:0.1.10b746a34e5597
openssh@1:8.4p1-5+deb11u1
1:8.4p1-5+deb11u4
1
nodered/node-red:3.0.2-18e2632a7a35dd
openssh@9.6_p1-r0
9.6_p1-r2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.